75/100 SECURITY SCORE

Certificate Information

Subject
C=US, ST=Illinois, L=Chicago, O=Jones Lang LaSalle IP, Inc., CN=sansites3.jll.com
Issuer
C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1
Valid From
January 22, 2026
Valid Until
August 21, 2026 203 days
Public Key
ECDSA 256 bit (P-256) Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
08:E0:F9:52:AF:3D:A5:E3:4E:21:E3:E9:13:37:3C:40:1B:5F:50:A6:E6:E3:30:B2:46:3B:C9:56:D7:AF:E8:DC
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

77 domains
adfs.integral.co.uk autodiscover.integral.co.uk cns.integral.co.uk concept.integral.co.uk conceptuat.integral.co.uk ibcm.integral.co.uk intuitivepfi.integral.co.uk lyncdiscover.integral.co.uk maintain.integral.co.uk origin-portal.integral.co.uk pki.integral.co.uk sip.integral.co.uk support.integral.co.uk vixtab.integral.co.uk vpn.integral.co.uk vpn01.integral.co.uk zertovpn.integral.co.uk consoleprd30.maintain.integral.co.uk esb.maintain.integral.co.uk esbprd20.maintain.integral.co.uk esbprd30.maintain.integral.co.uk esbprd40.maintain.integral.co.uk iceapi.maintain.integral.co.uk loginprd30.maintain.integral.co.uk maxicogprd20.maintain.integral.co.uk maxmif.maintain.integral.co.uk maxmifprd20.maintain.integral.co.uk maxmifprd30.maintain.integral.co.uk maxreportsprd30.maintain.integral.co.uk maxuiprd30.maintain.integral.co.uk maxuiprd40.maintain.integral.co.uk

Other domains in certificate

eul.afpaces.com portal.afpaces.com
bascomadvisors.com www.bascomadvisors.com
blue-api.dev.core.beifederation.com blue-api.predev.core.beifederation.com blue-web.dev.core.beifederation.com blue-web.predev.core.beifederation.com
coact.bewonder.co.uk hello.bewonder.co.uk reports.bewonder.co.uk
api.stg.buildingengines.com blue-api.stg.buildingengines.com blue-web.stg.buildingengines.com pmapi.stg.buildingengines.com
api.dottid.com app.dottid.com developer.dottid.com dottid.com graph.app.dottid.com resources.dottid.com scim.dottid.com server.app.dottid.com
api-dev.dottid.net appset.infra.dottid.net cd.infra.dottid.net demo.dottid.net dev.dottid.net graph.demo.dottid.net graph.dev.dottid.net graph.qa.dottid.net qa.dottid.net server.demo.dottid.net server.dev.dottid.net server.qa.dottid.net
dev.experiencecivis.com stg.experiencecivis.com www.experiencecivis.com
jll-marketplace.com www.jll-marketplace.com
prototype.valuations.jll.com sandbox.subscribe.jll.com sansites3.jll.com www.propiedades.jll.com
belux.ebrochure.jll.eu
www.residential.jll.lu